Interrogate the claim before the contract.

A polished demonstration proves that a path can be shown. Due diligence asks whether the path survives your data, systems, people, building constraints, commercial terms, and exit.

Ask for an evidence chain.

Write the operating problem, current baseline, promised mechanism, integration path, security and data obligations, acceptance test, owner, and exit condition in one page. If the vendor and buying team cannot agree on that chain, more features will not repair the decision.

Diligence in view

Test the delivery chain.

A product claim is only as strong as the hardware, integration boundary, and handover that support it.

Hands comparing an unbranded building sensor and network gateway01
Product — inspect what will actually enter the property.
Integration review with network cables, laptop, and building-system diagram02
Integration — identify interfaces and support ownership.
Building devices being transferred between protective equipment cases03
Exit — define data, hardware, and configuration handover.

Published 8 September 2026 · reviewed 9 September 2026. Editorial illustrations generated for Hamed Helped; they do not depict a named site, vendor, or client.

Decision criteria

Six gates between interest and commitment.

01Workflow

Problem fit

Name the operator, current process, failure or friction, changed action, and downstream handoff.

02Proof

Outcome evidence

Require a comparable baseline, observable outcome, measurement method, timeframe, and acceptance owner.

03Data

Rights & quality

Set source, access, validation, retention, sharing, model-use, export, deletion, and exit rights.

04System

Integration & support

Map dependencies, identifiers, interfaces, change windows, incident paths, and responsibility boundaries.

05Risk

Security & continuity

Review assets, identities, remote access, updates, logs, backups, recovery, and end-of-support decisions.

06Commercial

Durability & exit

Test pricing basis, implementation burden, ongoing services, dependencies, contract change, transition, and replacement.

Questions to ask

Make the vendor answer in your operating language.

  1. Show the current workflow.

    Which exact steps disappear, change, or move to a different person—and what new task is created?

  2. Show the denominator.

    When a percentage improvement is claimed, what population, baseline, time period, exclusions, and comparison produced it?

  3. Show the integration boundary.

    Which systems provide and receive data, who maintains each interface, and what happens when one is unavailable?

  4. Show the data exit.

    Which raw, normalized, configured, and derived data can the owner export, in what format, at what cost, and on what timeline?

  5. Show the failure path.

    How are security events, outages, unsafe states, errors, and disputed results detected, escalated, recovered, and evidenced?

  6. Show the end of the relationship.

    How are credentials revoked, integrations separated, configurations transferred, hardware handled, and operations sustained?

Evidence table

Do not let one document answer six different questions.

Claim or decisionEvidenceOwnerWhen checked
Workflow valueCurrent-state map, named user, baseline, pilot protocol, and acceptance thresholdOperationsBefore pilot approval
Integration feasibilityArchitecture, interfaces, data dictionary, responsibilities, test and rollback planSystem owner + ITBefore technical commitment
Security acceptanceAsset scope, identity and remote-access model, update and incident processes, recovery evidenceSecurity + operationsBefore connection
Data controlContract terms, permissions, quality rules, lineage, export sample, retention and deletion pathData owner + legalBefore signature
Commercial durabilityTotal cost model, service dependencies, change terms, support scope, exit and transition obligationsProcurement + financeBefore award and at renewal

Failure modes

Four ways a buying process drifts.

F-01

The demo becomes the baseline

A staged experience replaces evidence from the actual workflow and asset conditions.

F-02

Security arrives after selection

A preferred product is chosen before its identities, access paths, lifecycle, and recovery are visible.

F-03

Pilot means production

Temporary access, data handling, support, and exceptions quietly become the permanent architecture.

F-04

Exit is a future problem

Data, configuration, integrations, credentials, and operating knowledge cannot be transferred cleanly.

Apply the gates

Turn the diligence questions into a pilot go/no-go.

Run the scorecard

Evidence trail

Sources behind this guide

  1. 01
    UK PropTech AssociationInvestment Readiness Guide for PropTech Founders (external link)

    Current framework spanning legal, financial, regulatory, commercial, product, technology, and governance readiness.

  2. 02
    BOMA BEST Field GuideR1.1 Data Access and Ownership (external link)

    Owner/operator guidance on direct access to and export of system data.

  3. 03
    NISTGuide to Operational Technology (OT) Security — SP 800-82 Rev. 3 (external link)

    Primary risk-based OT security and lifecycle guidance.

  4. 04
    IoT Security FoundationBuilding Technology Procurement Guide (external link)

    Industry guidance supporting security governance during building-technology procurement.